BTP Lens runs on your machine and writes files to your disk. This page lists what it reads, what it keeps, and where requests go.
Principles
- Read-only. The HTTP client allows only
GETto the CF API. This is enforced per host by the egress allow-list inpackages/cli/src/net/allowlist.ts, and unit tests prove it. - No data leaves the machine. The allow-list is the only way out, and redirects are never followed. There is no telemetry.
- No personal data in any output.
- No secret values in any output.
Where requests go
| Host | Why | What is sent |
|---|---|---|
Your CF API (--api) |
inventory | GET only, with your token |
| Your UAA or login server (from the CF root) | token refresh or client credentials | POST /oauth/token only |
| Your log cache | from v0.2 | GET only |
api.osv.dev |
known vulnerabilities | public package names and versions from your SBOM |
endoflife.date |
runtime end-of-life dates | product names such as nodejs |
ui5.sap.com |
UI5 maintenance status | a request for /versionoverview.json |
registry.npmjs.org |
current @sap/* versions |
four fixed package names |
| Your app routes | the UI5 version served | one unauthenticated GET /resources/sap-ui-version.json per app, with no redirects; turn it off with --no-probe-routes |
Your CF token is sent to the CF API only. The allow-list refuses an Authorization header to any other host.
What is kept
The snapshot and reports contain only allow-listed fields. The parsers drop everything else before it is stored.
- Orgs and spaces: GUID and name.
- Apps:
- GUID, name, space, state, created and updated times, lifecycle type, and requested buildpacks.
- Credentials in buildpack URLs are removed.
- Current droplets:
- GUID, app, state, timestamps, stack, and the detected buildpack names and versions.
- Detect output is cut to 200 characters.
- For Docker droplets, the image reference with credentials removed.
- Findings: rule id, severity, app reference, evidence (facts such as dates and versions), remediation and links.
What is never kept
- User identities:
- User names, emails and IDs are never stored.
- Audit-event
actorfields are dropped when the events are read. - App annotations and labels (which often hold owner emails) are not collected.
- Secrets:
- Tokens, refresh tokens and client secrets.
- Environment variable values; with
--deep, only variable names are kept. - Service credentials and service keys.
- Droplet
execution_metadataand start commands (which can contain passwords).
- Logs are not read in v0.1.
A test scans the snapshot and every report format for planted secrets, emails, JWTs and credential URLs (packages/cli/test/e2e/leak.test.ts).
Side effects in your landscape
GET requests do not change anything. One read is audited by Cloud Foundry: with --deep, reading an app’s environment variables creates an audit.app.environment_variables.show event for that app. Tell your security team before you run --deep scans.
User-level usage (v0.2)
Usage per user is not collected in v0.1. When it arrives in v0.2, it will be opt-in. User identifiers will be hashed with a random salt created for each scan and never stored, and only aggregated counts will be reported.
Retention
Snapshots and reports are ordinary files in your --out folder. Delete them when you no longer need them. BTP Lens keeps no other copy.
This page is the file docs/privacy.md from the public repository at commit 9fe7d0db6498, synced on 3 October 2026. Apache-2.0. To change it, open a pull request there.